Our security, stated honestly
We hold clients to a high security standard — we hold ourselves to the same one. Here are the controls we actually have in place, our compliance roadmap, and who we rely on. We only claim what's true.
Security controls in place
MFA enforced everywhere
Multi-factor authentication on every system we operate — no exceptions, no shared accounts.
Least-privilege access
Staff access only what they need, revoked immediately when no longer required.
Endpoint protection
EDR on all devices with 24x7 monitoring and rollback capability.
Encrypted backups
Data encrypted at rest and in transit, with quarterly restore testing.
Background-checked staff
Every technician and contractor is background-checked before accessing client systems.
Patching discipline
Critical patches within 7 days; routine patches monthly. Vulnerability scanning on a schedule.
Where we are, where we're going
Our internal practices follow the CIS Controls framework as a baseline. We don't claim a certification we don't hold.
We're pursuing SOC 2 as the business grows. This page will update with verified status as milestones are reached.
We do not claim SOC 2, ISO 27001, or any certification we have not earned. Trust is built on honesty.
Who we rely on
These vendors process client data on our behalf. We review them for security and list them transparently.
| Vendor | Purpose | Location |
|---|---|---|
| HaloPSA (PSA) | Ticketing, client portal, billing | US (cloud) |
| NinjaOne (RMM) | Remote monitoring & management | US (cloud) |
| Microsoft 365 | Email, productivity, identity | US / regional |
| Cloud backup provider | Immutable backup storage | US (cloud) |
| Base44 (hosting) | Website hosting & forms | US (cloud) |
Responsible disclosure
Found a security issue with our website or services? Email security@tekgenius.com with details. We acknowledge reports within 2 business days and work in good faith with researchers. A security.txt file is published at /.well-known/security.txt.